Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 5/1469
7.2
CVE-2026-18978

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all version

7.2
CVE-2026-18324

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro

7.6
CVE-2026-38822

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client s

7.1
CVE-2026-38821

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on th

8.3
CVE-2026-38820

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas

8.8
CVE-2026-82072

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins

8.8
CVE-2026-78037

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated atta

8.1
CVE-2026-77977

Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive

7.5
CVE-2026-76945

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An

7.5
CVE-2026-76940

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout m

8.8
CVE-2026-76060

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HT

8.8
CVE-2026-75814

The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management inte

7.5
CVE-2026-75813

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access

8.8
CVE-2026-75419

go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/s

7.5
CVE-2026-75418

A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An at

7.2
CVE-2026-75417

A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within applicat

8.8
CVE-2026-75339

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload

7.5
CVE-2026-73809

A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web manag

7.5
CVE-2026-67560

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A

8.1
CVE-2026-54330

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

7.1
CVE-2026-54085

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

8.1
CVE-2026-54083

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. T

7.9
CVE-2026-44629

Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one

8.8
CVE-2026-39944

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

7.5
CVE-2026-38350

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows atta

7.5
CVE-2026-38349

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attacke

7.5
CVE-2026-38348

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denia

7.5
CVE-2026-38346

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attacke

8.8
CVE-2026-18965

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on th

7.4
CVE-2026-18717

ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker

8.9
CVE-2025-30156

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

7.1
CVE-2026-81838

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 thr

8.2
CVE-2026-81730

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers with

8.1
CVE-2026-81728

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with

7.1
CVE-2026-81529

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C

8.1
CVE-2026-81525

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace ide

8.1
CVE-2026-81522

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embed

7.5
CVE-2026-77438

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public shar

7.5
CVE-2026-76640

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisio

8.8
CVE-2026-76639

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows networ

7.7
CVE-2026-75889

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor reso

8.2
CVE-2026-59324

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, conc

8.2
CVE-2026-59316

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When usi

8.0
CVE-2026-59307

An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all

7.6
CVE-2026-59284

There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commo

7.5
CVE-2026-59282

Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a

8.8
CVE-2026-54721

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1

7.2
CVE-2026-54718

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an

8.1
CVE-2026-53580

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-downlo

7.5
CVE-2026-37198

An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via suppl

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started